From owner-freebsd-questions Fri Feb 22 3: 0:34 2002 Delivered-To: freebsd-questions@freebsd.org Received: from rwcrmhc54.attbi.com (rwcrmhc54.attbi.com [216.148.227.87]) by hub.freebsd.org (Postfix) with ESMTP id 89FF837B417 for ; Fri, 22 Feb 2002 03:00:29 -0800 (PST) Received: from blossom.cjclark.org ([12.234.91.48]) by rwcrmhc54.attbi.com (InterMail vM.4.01.03.27 201-229-121-127-20010626) with ESMTP id <20020222110029.SRTS1214.rwcrmhc54.attbi.com@blossom.cjclark.org>; Fri, 22 Feb 2002 11:00:29 +0000 Received: (from cjc@localhost) by blossom.cjclark.org (8.11.6/8.11.6) id g1MB0Pb84167; Fri, 22 Feb 2002 03:00:25 -0800 (PST) (envelope-from cjc) Date: Fri, 22 Feb 2002 03:00:25 -0800 From: "Crist J. Clark" To: Simon J Mudd Cc: freebsd-questions@FreeBSD.ORG Subject: Re: ipfw and getting the interface logged Message-ID: <20020222030025.M48401@blossom.cjclark.org> References: <861yfen1tv.fsf@unicorn.ea4els.ampr.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <861yfen1tv.fsf@unicorn.ea4els.ampr.org>; from sjmudd@pobox.com on Thu, Feb 21, 2002 at 07:10:04PM +0100 X-URL: http://people.freebsd.org/~cjc/ Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG On Thu, Feb 21, 2002 at 07:10:04PM +0100, Simon J Mudd wrote: > sjmudd@pobox.com (Simon J Mudd) writes: > > > Feb 21 16:13:56 unicorn /kernel: Connection attempt to TCP 44.133.228.2:6000 from 44.133.228.5:2187 > > Feb 21 16:13:57 unicorn /kernel: Connection attempt to TCP 44.133.228.2:6000 from 44.133.228.5:2188 > > Typical "not reading the manual" shows me that this is in > /var/log/messages and in fact the ipfw logging is working in > /var/log/security > > I'm just surprised that the firewall_log_in_vain sysctl doesn't > produce the output in the same file as the ipfw output. Perhaps it > would make sense to duplicate this. That actually may be a good idea. log_in_vain is presently logged to the 'kern' facility which is why it ends up in messages and not security. You can change your syslog.conf so they go there. I think I'll propose changing log_in_vain to use the 'security' facility. > Now I can see what's going on I can probably find the problem with my > rules. Like I said a number of times, ;) there is no problem with your firewall rules. Your X server is not listening. -- Crist J. Clark | cjclark@alum.mit.edu | cjclark@jhu.edu http://people.freebsd.org/~cjc/ | cjc@freebsd.org To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message